Defined term
Severe incident
The second reporting trigger, aimed at the product's own security.
LAW Defined in Article 3 (Art. 3(44)). The verbatim definition is in the official text of Article 3; only the Official Journal is authentic.
sha256:27b7c6c64c773001… · CELEX 32024R2847A severe incident having an impact on the security of the product is the second Article 14 trigger F-030, running the same 24-hour and 72-hour notification rhythm as the vulnerability limb F-029. The phrase to underline is "of the product": this is about incidents that negatively affect, or are capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that have led or could lead to the introduction or execution of malicious code, not every operational outage a company suffers F-030.
Verified facts this page relies on
- F-030 Actively exploited vulnerability (Art. 3(42)): reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. A severe incident having an impact on the security of the product (Art. 14(5)) is one that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or is capable of leading to the introduction or execution of malicious code. Art. 3(42), Art. 3(44), Art. 14(5)
- F-029 Severe incident having an impact on the security of the product: early warning within 24 hours; incident notification within 72 hours; final report within one month after the incident notification. Art. 14(3)–(4)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.